Privacy Policy
What CandleDraw knows about you, who else can see it, how long it is kept, and how to get rid of it. No analytics, no advertising, no tracking.
Last updated 2 September 2026
1.Who we are
CandleDraw is operated by JG Tromp, trading as CandleDraw. For data we decide the purpose of — your account, your drawings, your subscription — we are the data controller.
For data an educator brings to the platform, the roles differ: see Cohorts, assignments, and what your educator sees.
Data-protection questions and requests: privacy@candledraw.com.
2.The short version
There are no analytics, no advertising, no tracking pixels, and no third-party trackers anywhere in CandleDraw. We do not profile you, and we do not sell or share your data with anyone for their own purposes.
We hold what running the product requires: an account, your drawing, your subscription status, and — if you join a class — your cohort work. Your drawings are private to you unless you submit them for an assignment. We do not use them to train machine-learning models.
The rest of this page is the detail behind those sentences.
3.What we collect, and why
- Account
- Your email address, a display name (defaulting to the local part of your email), and an avatar URL if your sign-in provider supplies one. Needed to have an account at all, and to sign you in.
- Your drawing
- One document per account: candles, annotations, studies and chart settings, stored compactly. Needed so your work follows you between devices.
- Preferences
- Theme, toolbar layout, chart defaults, branding settings. Mostly kept in your browser; see What is stored in your browser.
- Subscription
- Your Creem customer and subscription identifiers, your plan, its status, billing cadence, and when the period ends. Needed to unlock what you paid for. We never receive your card details.
- Cohort and coursework
- If you are an educator: your cohorts, curriculum, assignments, and referral codes. If you are a student: which cohorts you belong to, and the canvas you submitted for each assignment, with its timestamp.
- Support messages
- The category, subject and body of anything you send through the support form, plus your account email so we can reply.
- Abuse prevention
- For support submissions only: a salted SHA-256 hash of your IP address, never the address itself, plus a timestamp. Enough to recognise a repeat sender, not enough to identify one.
We do not ask for, and have no use for, your date of birth, phone number, postal address, or any financial information beyond what Creem handles.
4.Our legal bases
Under the GDPR, we rely on:
- Performance of a contract — your account, your document sync, your cohort and assignment data, and your subscription. Without these the service cannot be delivered.
- Legitimate interests — keeping the service secure and abusive traffic out (the IP hash, the rate limits, the anti-bot challenge), and answering your support messages. We have weighed these against your interests and kept the data minimal, which is why an IP is hashed rather than stored.
- Legal obligation — retaining invoices and tax records for the period our law requires.
We do not rely on consent for anything above, because none of it is optional to the service. If we ever add something that is optional, it will be opt-in and separately explained.
5.Cohorts, assignments, and what your educator sees
When an educator adds you to a cohort, they decide what work is set and how it is reviewed. For that data, the educator is the controller and we process it on their behalf, under our Data Processing Agreement with them; it requires them to give you proper notice and to have any parental consent their law requires.
An educator can see:
- the assignments they set, and every submission returned to them;
- the members of their cohorts;
- the profile of any student who signed up through their referral link — including your email address and display name. This is worth reading twice: a referral link is not anonymous, and following one before signing up means the educator who shared it can see the account you create.
An educator cannot see:
- your private drawing on the canvas. Only a canvas you actually submit for an assignment is shared, and only with the educator who set it;
- anything belonging to a student who is not in their cohort and did not use their link;
- your subscription or payment details.
Row-level security in the database enforces each of these boundaries, rather than the application asking politely.
6.Children
CandleDraw is not designed for children, and you must be at least 16 to create your own account.
A student under 16 may only be enrolled by an educator who has obtained parental consent where their law requires it. That responsibility sits with the educator, who chose to bring the student onto the platform; we have no direct relationship with the student's parents and no way to verify consent ourselves.
If you believe a child has an account without proper consent, email privacy@candledraw.com and we will delete it.
7.Who else touches your data
We use a small number of providers to run the service. Most process data on our instructions; Creem is an independent seller and controller for payment data.
- Supabase
- Database, authentication, file storage, and server-side functions.
- Vercel
- Hosting and delivery of the application itself.
- Creem
- Payments, invoicing, and the customer portal. Creem is the merchant of record for paid subscriptions, not a processor acting on our instructions — it is the seller, it issues your invoice, and it is a controller in its own right for the payment data it holds. Its own privacy policy governs that data, and a billing address or card detail you give at checkout is given to Creem rather than to us.
- Resend
- Sending transactional email — sign-in links, confirmations, password resets, and support messages.
- Cloudflare
- The Turnstile anti-bot challenge on the support form. Turnstile is used specifically because it does not track visitors across sites.
- Microsoft
- Our support mailbox, where your messages to us are received and stored.
Some of these providers operate outside the European Economic Area. Where data moves outside it, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
We will update this list before adding a provider, and treat a new category of recipient as a material change under our Terms.
8.What is stored in your browser
CandleDraw uses your browser's local storage, not advertising cookies. Nothing stored there is read by any third party, and none of it follows you to other sites — which is why there is no cookie banner.
- Your sign-in session
- Kept by the authentication library so you stay signed in. Cleared when you sign out.
- Your working document
- A local copy of your drawing and when it was last changed, so the canvas opens instantly and the newer copy wins when it syncs.
- Your preferences
- Theme, toolbar arrangement, chart defaults, branding, and dialog sizes.
- A referral code
- If you arrived through a referral link, the code is held until you sign in and it is claimed, then removed.
Clearing your browser storage signs you out and discards local preferences. Your drawing is safe: the synced copy is restored when you sign in again.
9.Watermark logos are public
If you upload a logo for chart watermarking, it is stored in a public storage bucket so it loads on your exported charts without a signed link. Anyone who knows or guesses the URL can fetch it. Bucket listing is restricted to the signed-in owner of that logo prefix; public reachability does not make other users’ logo directories browsable through CandleDraw.
This is a deliberate trade for export speed, and it is the one place in the product where something you upload is not private. Upload only logos you are happy to have publicly reachable.
10.How long we keep things
- Account, document, preferences
- Until you delete your account.
- Cohort membership and submissions
- Until you or the educator delete them, or until your account is deleted.
- Abuse-prevention IP hashes
- Targeted to expire within 24 hours and removed during the next ledger cleanup.
- Support conversations
- Kept in the support mailbox for up to 24 months, then deleted.
- Invoices and payment records
- Creem retains invoices, transaction, tax, customer, and any affiliate records under its own legal obligations and privacy notice. Account deletion removes CandleDraw’s local subscription and checkout mappings; it cannot erase the independent seller’s statutory records.
- Referral-earnings ledger
- Kept after account deletion for financial accountability, in anonymized form: amounts, dates and internal references that no longer resolve to a person once the account is gone.
- Backups
- Deleted rows may persist until encrypted backups roll off under the hosted provider’s configured schedule. Backups are used only for disaster recovery; if one is restored, the deletion must be replayed.
11.Deleting your account
You can delete your account from your profile settings, or by emailing privacy@candledraw.com. Deletion cascades: your profile, your synced document, saved projects, cohort memberships, submissions, local subscription mappings, entitlements, uploaded logos, and referral codes all go with it. If you are an educator, your cohorts, curriculum, assignments, and students’ submissions to those assignments are deleted too.
Four records are not synchronously erased by that flow:
- Creem billing records, which the independent merchant of record retains under its legal obligations and privacy notice.
- Support correspondence in delivery systems and our mailbox, retained for up to 24 months unless a verified request or legal obligation requires a different outcome.
- Abuse-prevention records of support submissions, which are detached from your account rather than erased, so that deleting an account cannot be used to erase evidence of an in-flight abuse burst. They contain a hashed IP and a timestamp, and are targeted to expire within 24 hours.
- Referral-earnings records, where an account took part in the referral program as the educator or as a referred subscriber. What has been paid and what is owed must survive the accounts it concerns, so those ledger rows are kept — in anonymized form: deletion removes every name, email and profile they could point to, leaving amounts, dates and internal references that no longer identify anyone.
Educators: deleting your account deletes your cohorts, curriculum, assignments, and with them your students' submissions to those assignments. Your students keep their own accounts and their own drawings. Export anything you need first.
12.Your rights
If the GDPR or UK GDPR applies to you, you have the right to access your data, to correct it, to have it deleted, to restrict or object to how we use it, and to receive a portable copy. You also have the right not to be subject to automated decision-making — we do not do any.
Email privacy@candledraw.com to exercise any of these. We respond within 30 days and we do not charge for it. We may ask you to confirm you control the account's email address, which is the only identity check we can make without collecting more data than we hold.
For much of this you do not need us. Your drawing exports in a click, and your profile settings hold both “Download my data” — a JSON file of your profile, plan, synced drawing, saved projects, cohort memberships and submissions, plus anything you own as an educator — and account deletion.
If you think we have handled your data badly, please tell us first — and you are entitled to complain to your national data-protection authority regardless of what we say.
13.Security
Data is encrypted in transit and at rest. Access between accounts is enforced in the database with row-level security, so a bug in the interface cannot expose one user's work to another; the rules are written per table and default to denying access.
Passwords are hashed by our authentication provider and are never visible to us or stored by us. New and changed passwords are checked against known breach databases and rejected if they appear in one. Card details never reach our servers.
No system is perfect. If we discover a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours and tell you directly where the risk to you is high.
Found a vulnerability? Email privacy@candledraw.com rather than disclosing it publicly, and we will work with you on it.
14.Changes to this policy
We update this page when the product changes. For a material change — a new category of data, a new recipient, a new purpose — we will email you before it takes effect, as our Terms require.
The date at the top of this page always reflects the current version.
15.Contact
- Privacy and data requests
- privacy@candledraw.com
- Support and contract questions
- support@candledraw.com
Signed-in users can also reach us through the Support tab in the profile menu, which routes to the same inbox.